Impact
A flaw Central component with network access via HTTP to fully compromise the application. The vulnerability allows the attacker to bypass authentication and gain unrestricted control, potentially tampering with or redirecting the security services that protect other Fusion Middleware products. This platform and broader impact due to the scope change property of the flaw.
Affected Systems
The vulnerability affects Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0. These are the only officially supported versions impacted, and attackers can target them via HTTP without authentication.
Risk and Exploitability
The CVSS is 10.0, indicating maximum severity for confidentiality, integrity, and availability. The EPSS indicates a very low exploited probability (<1%), and the flaw is not currently listed in CISA’s KEV catalog. The likely attack vector is a network-based HTTP request that does not require authentication, making it easily exploitable. Due to the scope change, exploitation of this takeover and potentially affect other connected services.
OpenCVE Enrichment